Sunday, June 21, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Identity & Access Security Bloggers Network 

Home » Security Bloggers Network » Disorder in the Court: Unintended Consequences of ATO

SBN

Disorder in the Court: Unintended Consequences of ATO

by Enzoic on November 19, 2024

The most common ATO threat that individuals and businesses imagine affecting them is their accounts getting hijacked- e.g. a threat actor uses credential stuffing to login to your netflix account, and enjoys some free entertainment on your dime (or sells the account for a few dollars)…or in a more serious scenario, accesses an employee’s corporate email to send phishing emails to other employees and gain access to the internal network to install ransomware.

But why would you worry about ATO happening to people who have nothing to do with you?

A recent FBI alert (as reported by Brian Krebs) highlighted an interesting and dangerous consequence of account takeover (ATO). As the FBI alert states, “cybercriminals are likely gaining access to compromised US and foreign government email addresses and using them to conduct fraudulent emergency data requests.” These email accounts are then used to make Emergency Data Requests, a type of legal requisition for information or action that bypasses much of the usual authorization process. The personal information obtained can be used for scamming, but the FBI warns that these requests can also be used to freeze and seize bank and cryptocurrency accounts.

While social engineering isn’t usually part of our immediate purview in the world of compromised credential research, these scams begin with a compromised email account from a government or law enforcement agency, which come from “mostly email-based phishing, and credentials that are stolen by opportunistic malware infections and sold on the dark web” according to Krebs’ article. It’s worth noting that the agency itself does not have to be compromised: because of credential and password reuse, cybercriminals may be able to take over an account merely because someone used their work email for something like a Spotify account, or to sign up for a gym membership, and re-used a compromised password.

Consequences of ATO: How to Hack Your Password

We may not be social engineers here at Enzoic (well, except perhaps the researchers assigned to infiltrate cybercrime forums), but we do know passwords. It may seem like a simple concept, but the amount of perpetuated misunderstanding around passwords out there belies the idea that even many cybersecurity experts really understand user behaviors and vulnerabilities. Every year we see at least a few types of “most popular password” lists, which rarely provide any new information, and can create a false sense of security.  For example, the Identity Theft Resource Center’s Weekly Breach Breakdown on November 1st of this year repeated some misleading statistics and some dangerous advice on choosing passwords from sources that one would expect to be highly reputable. They reference this list of ‘most common passwords’ for 2024, which informs us that the most common password in 2024 is ‘123456’. But what does this actually mean?

If organizations and users are protecting themselves appropriately, then we have no way of knowing what the most used passwords are. These types of statistics are highly susceptible to confirmation bias, in that the weakest passwords are compromised the most, and thus most prevalent when looking for compromised passwords.

Compromised credentials are also constantly shared and re-shared in ever-larger aggregated lists that include passwords from decades ago, so if we count these each time we see them, the ones that have been around the longest will seem most prevalent. These days, the reality is that, even though password complexity requirements have been discredited and dropped by NIST, most applications have requirements that would no longer allow 123456. So all these ‘top passwords’ lists do is provide a false sense of security.

Myths About Password Cracking Timeframes

The podcast also repeats claims that ‘a 12-character password with just lowercase letters will take 1,000 years to crack.’ This is a rather arbitrary number that varies enormously depending on the type of hashing algorithm and amount of computing power used, but what it actually refers to is the amount of time required to calculate all possible combinations, i.e. to crack every possible lowercase 12-character password. The reality is far different. We humans are notoriously terrible at choosing passwords: we overwhelmingly use words from our native language, letter combinations that make pronounceable sounds, and strings that are easy to type on a QWERTY keyboard layout. This vastly reduces the actual amount of character space that is most likely to be used for passwords, and thus means that a non-random password stands the risk of being cracked much, much faster.

And due to password re-use, one of the first techniques that hackers try for password cracking is to use lists of previously compromised passwords (research indicates over 8 billion unique passwords). As so many have already been compromised, even things that far exceed the typical “complexity” requirements are likely to be extremely susceptible to fast cracking (if not outright vulnerable to credential stuffing).

Avoiding Dangerous Password Advice

The most dangerous piece of advice provided in the podcast is that your password should be “something you can remember.” As a general rule, the easier your password is to remember, the easier it is to crack, and the more likely it is to be susceptible to account takeover. The best passwords are next-to-impossible to remember in that they are highly random, and do not exhibit any of the patterns that make things easy for humans to remember. If you cannot make use of a secure password manager (not a browser-based password manager!) and must memorize your password, make sure that it is quite long, e.g. based on a phrase instead of a single word, and makes use of a wide array of numbers, symbols, and capital letters- not just a lone exclamation point, or number sequences like 123.

FAQs

1. What are the most dangerous consequences of ATO for individuals and businesses?
The consequences of ATO can range from personal account hijacking, such as unauthorized access to streaming services or social media accounts, to more severe impacts like corporate email breaches. In corporate scenarios, ATO can lead to phishing campaigns, ransomware attacks, or unauthorized Emergency Data Requests, which may result in the freezing of bank and cryptocurrency accounts.

2. How can social engineering amplify the consequences of ATO?
Social engineering plays a significant role in ATO by leveraging compromised email accounts from trusted organizations, such as government or law enforcement agencies. These attacks often exploit reused passwords or phishing schemes, enabling cybercriminals to conduct fraudulent activities like Emergency Data Requests or scamming individuals with stolen personal data.

3. What are the best practices to avoid the consequences of ATO?
To mitigate the consequences of ATO, avoid reusing passwords across accounts, use a secure password manager to create complex and unique passwords, and regularly monitor accounts for compromised passwords. Businesses should enforce strong cybersecurity practices, including multi-factor authentication, automated tools to remediate compromised passwords, and regular employee training to recognize phishing attempts and other ATO tactics.

 

AUTHOR


Dylan Hudson

Dylan leads the Threat Research team at Enzoic, developing and implementing cutting-edge threat intelligence infrastructure to help protect users and organizations from cyberattacks. When not at work, he can be found hiking and biking in the Rocky Mountains or playing traditional Celtic music on various stringed instruments.

*** This is a Security Bloggers Network syndicated blog from Blog | Enzoic authored by Enzoic. Read the original post at: https://www.enzoic.com/blog/disorder-in-the-court-unintended-consequences-of-ato/

November 19, 2024November 19, 2024 Enzoic account takeover, Password Security, Threat Intel
  • ← Why Shadow APIs provide a defenseless path for threat actors
  • Unraveling Raspberry Robin's Layers: Analyzing Obfuscation Techniques and Core Mechanisms →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

3 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

4 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

4 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Databricks Acquires Cybersecurity Startup Panther Labs to Fortify AI Defense
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks
France to Stop Certifying Products Without Quantum-Safe Encryption in 2027
FortiBleed Leak Exposes VPN Credentials for Nearly 74,000 Fortinet Devices
Kodak Confirms Data Breach Claimed by ShinyHunters Extortion Gang
Microsoft Defender Zero-Day Privilege Escalation Vulnerability (RoguePlanet)
GitHub Locks Down npm: What the New Install Defaults Mean for Your Supply Chain
973 MCP Packages, 71% Single-Maintainer: A Practitioner’s Guide to AI Developer Security

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | 3 days ago 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

Job Seekers Make for Vulnerable Targets
Cybersecurity Data Privacy Data Security Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Job Seekers Make for Vulnerable Targets

June 19, 2026 Teri Robinson | 2 days ago 0
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | 3 days ago 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 4 days ago 0

Security Humor

Fortinet® Follies

Fortinet® Follies

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
Managing the AppSec Toolstack
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.